| E03 Public API and control-plane core | Rust axum API owning orgs, projects, instances, members, keys, with OpenAPI. | | Phase 1 · MVP | — |
| E12 Security and compliance | Identity, RBAC, secrets, audit, data confidentiality, HIPAA secure hosting, SOC 2. | | Phase 1 · MVP | — |
| E04 Provisioner and operator | Instance CRD, saga workers, in-cell operator with engine adapters. | | Phase 1 · MVP | - Customer deletes on plans with retention (all paid plans) stayed `deleting` in the API for the whole retention window: no event reported their completion
|
| E05 Gateway | Pingora TCP/TLS gateway with SNI routing, allow-lists, byte accounting. | | Phase 1 · MVP | - Gateway MySQL handshake: backend SSLRequest carried the gateway's charset/flags, MySQL 8.4 rejects the mismatch (Bad handshake) and every session got the gateway's capability flags; only ER_ACCESS_DENIED (1045) counts as an auth failure; mysql CLI snippets need --tls-sni-servername
|
| E20 API security, threat detection and risk management | Separated API planes, edge protections, security event pipeline, risk portal (docs/20). | | Phase 1 · MVP | — |
| E08 Backups and restore | Per-plan policies, engine-native backups, verification, restore, PITR. | | Phase 1 · MVP | - Operator/provisioner consume backup.schedule_desired/run/verify/restore_requested → BackupSchedule CR, agent Jobs, restore saga; metering consumes usage.backup.v1
- zb-backup-store: in-cell object store on a PVC so single-server cells can take backups
|
| E11 Infrastructure and cells | Terraform, Argo CD, Helm, Karpenter, cells per tier and region. | | Phase 1 · MVP | - zbops deploy CLI (ported from Capsolving capzy) for single/multi-node k3s
|
| E10 Admin portal | Separate staff portal and admin API behind zero-trust. | | Phase 1 · MVP | - Staff Google sign-in did not land in the admin portal: the SameSite=Strict session cookie was withheld after the IdP-started redirect
- Staff plan and quota overrides did not show in the customer portal (Instance quota reached 1 of 1); metering ignored plan overrides
- Custom domains on the single-server cell: issuer, _acme-challenge CNAME, certificate status, billing
- Portal org features on the real API: Alerts, Audit log (list, export, SIEM), Invoices, Spending cap, Compliance settings, Profile
- Instance lifecycle from the portal: resize, storage grow, version upgrades, maintenance windows, placement
- ClickHouse backups fail (manual backups on 2026-10-06 ended failed)
- Web console for every engine (ClickHouse, QuestDB, CouchDB, InfluxDB, TypeDB, Qdrant, Weaviate, DuckDB, libSQL)
|
| E29 Go rewrite | Every server-side service rewritten in Go with feature, API, test and live-behaviour parity gates; Rust and TS server code deleted at cutover (docs/24, ADR-0009). | | Phase 1 · MVP | - Port services/api to Go (spec-first from openapi/api.json; same migrations, RLS, outbox, teams, SSO/SCIM, approvals, webhooks, reveal, instance ops, SSE events)
- Port services/admin-api to Go, extracting openapi/admin.json from the utoipa routes first (110 operations)
- Port billing from TypeScript to Go with its own rating ledger (usage events → rating → ledger → invoices; Stripe as a channel), entitlements, dunning, credits, sync-plans
- Port notify, integrations (GitHub/Vercel apps, branch databases), mcp (official Go MCP SDK) and console-ai from TypeScript to Go
- New services/cell-agent (pull model): outbound mTLS gRPC stream to the control plane, desired-state apply, status/usage over Kafka with produce-only credentials
- Port services/operator and the 18 engine adapters to Go (controller-runtime; upstream operator types), plus the console proxy
- Port services/provisioner to Go: sagas, scheduling (incl. dedicated-cell), leases in Valkey, pull-model transport
- Port metering, metering-agent, audit, sentinel, eventsctl and synth to Go
- Port backup, backup-agent, backup-store, migrate-agent and duckdb-server to Go
- Port the gateway to Go: TCP/SNI proxy with wire modules (postgres, mysql, resp, mongodb, http/h2/websocket, sql-https), project routes, byte accounting, allow-lists, pause/wake, mTLS
- Port the zb CLI to Go (cobra; identical command tree, `zb local` engines without Docker, docs, D1/docker helpers)
- Cutover: delete Cargo.*, crates/, rust-toolchain.toml, deny.toml and every TS server package; update CLAUDE.md, README, docs/02, docs/14, runbooks, website docs; parity check all green
- Docs for the Go architecture: rewrite docs/02 (tech stack), docs/14 (repo layout), docs/01 §2-3 service table; update the 35 files that reference Rust/cargo/crates as their services are ported
|
| E13 Engines | 18 engines via operator-backed and simple adapters. | | Phase 1 · MVP | - Wave 1 engines live: Postgres, MySQL, Valkey, FerretDB, libSQL (adapters, wire, backups, synthetics)
- Wave 2 engines: MariaDB, Redis 7.0, MongoDB (Percona), CouchDB, Meilisearch, Qdrant, InfluxDB 3, ClickHouse, TimescaleDB
- Wave 3 engines: DuckDB server shim, TypeDB, Weaviate, QuestDB
- Read replicas and HA for Postgres and MySQL
- Database branching (copy-on-write via CSI volume snapshots) for Postgres and MySQL
- Engine version refresh: TypeDB 3.13, Weaviate 1.39, QuestDB 10.0, CNPG chart 0.29/operator 1.30 (barman plugin migration before 1.29), Redis 7.0 EOL review
- Migration Jobs name no ServiceAccount: every migrate-agent Job in inst-* is refused (serviceaccount default not found)
- Engine smoke 2026-10-05 fixes: MariaDB app user cannot use other databases + backup 404; Meilisearch OOM on f0 (cap MEILI_MAX_INDEXING_MEMORY per size or raise min size); DuckDB backup quiesce curl has no retry (kube-router new-pod race); Qdrant datadir tar fails on live files (use snapshot API, ZB-302); TimescaleDB in-place restore Job fails; TypeDB/Valkey in-place restore unsupported
- Code vs docs findings from the README pass: ClickHouse backups are full not incremental and skip RBAC; ClickHouse restore Job does not mount the data volume; ClickHouse HA not orderable (catalogue lacks ha feature); InfluxDB Flight gRPC needs h2 upstream; InfluxDB/TypeDB rotation and restore/branch keep the source admin credential; Weaviate revealed username
- Simple-family storage grow changes the StatefulSet volumeClaimTemplates (immutable): verify on a cell and expand the PVC directly instead; CouchDB runtime config not persisted across restarts
- Migrations: target database defaults to the source name but app cannot create databases (nothing sets zb.io/target-database); copy_and_sync runs as app without CREATE SUBSCRIPTION / replication admin rights; API accepts copy_and_sync for MariaDB though the plan is MySQL-only; MySQL reverse sync promised but refused
- MySQL rotation never discards the old password; placement change regenerates credentials (write_secrets stub); MySQL 8.0->8.4 treated as minor with an impossible rollback; MongoDB HA db Service selects every member (writes can hit a secondary); TimescaleDB/MariaDB catalogue features missing so HA/replicas/pooler are refused; ServiceMonitor targets a metrics port no db Service has
- Backup agent pods carry the db Service selector labels: during a backup the Service routes customer (and quiesce) traffic to the agent pod; select engine pods only (zb.io/component=engine) in every db Service
- Simple family runtime fixes: Valkey maxmemory unset with noeviction (OOM kill instead of refusing writes); Meilisearch MEILI_MAX_INDEXING_MEMORY per size; migration Jobs connect with rediss/https to plaintext pods; rotation kills the old credential at restart while the API promises 10 min; upgrade/resize marked done before db-0 restarts (status ignores update revision); resume can exceed the gateway's 30 s hold; API accepts in-place restore for engines the provisioner refuses
- Docs truth for simple engines: Redis licence boundary is 7.4 not 7.2 (docs/05); libSQL docs promise auth tokens and bottomless PITR (basic auth + snapshot only; catalogue says libsql_bottomless pitr true); Valkey docs promise a limited ACL user; DuckDB Cargo licence Apache vs MIT and stale v1.3/--pg mentions; docs/09 AOF shipping not implemented
|
| E30 Kafka-only eventing | One event backbone: protobuf schemas, topics and tiers, outbox relay, idempotent consumers, replay, NATS removed (docs/24 §6, ADR-0010). | | Phase 1 · MVP | - Per-cell Kafka credentials (SASL user per cell, produce-only ACLs over TLS) and spill buffers in cell-agent, gateway and metering-agent
- Move every JetStream consumer to Kafka consumer groups as services are ported; provisioner leases to Valkey; `cell.<id>.status` topics
|
| E02 Design system and website | Capzy-style light/dark design system, marketing site, pricing, docs. | | Phase 2 · Operate at scale | — |
| E19 Migrations and connectivity docs | Move databases in from any provider, local servers or files; publish connect/Kubernetes/platform guides (docs/19). | | Phase 2 · Operate at scale | — |
| E22 App auth | Auth-as-a-service for customers' end users: passwords, magic links, OAuth, MFA, SAML, user admin, Supabase-compatible API (docs/23 §5.2). | | Phase 2 · Operate at scale | - Magic links, email OTP, email verification and password reset with customer SMTP and editable templates
- SAML 2.0 SSO for end users of a project (Team add-on, included on Enterprise)
- Password policies, leaked password protection (HaveIBeenPwned k-anonymity), session controls (time-box, inactivity timeout, single session) and per-project auth audit log
- Third-party auth: accept JWTs from Clerk, Auth0, Firebase Auth, AWS Cognito and WorkOS as project auth (trusted JWKS, role/claims mapping) at the gateway and data API
- Web3 sign-in: Sign-In with Ethereum (EIP-4361) and Sign-In with Solana
|
| E32 Database platform and Studio | Supabase-parity database features and studio tooling: extensions, vectors and embeddings, cron, queues, vault, FDW, declarative schemas, pipelines, table editor, schema designer, policy editor, advisors, AI assistant, log explorer and drains, full local dev (docs/23 §11). | | Phase 2 · Operate at scale | - Vector database and automatic embeddings: pgvector + HNSW, a trigger→queue→function pipeline that generates embeddings with a configured model, AI integration docs
- Foreign data wrappers (wrappers): Stripe, Firebase, S3, ClickHouse, BigQuery, Airtable, Postgres FDW with a portal UI
- Declarative schemas: `zb db pull|diff|push` schema-as-code with generated migrations, branch-aware
|
| E21 Platform foundations | Project endpoint, project keys and JWTs, primary database, catalogue meters/sizes/quotas, metering, portal shell, safety baseline for customer code (docs/23 §5.1, §6, §7). | | Phase 2 · Operate at scale | - Project API keys (publishable/secret) and per-project JWT signing keys with JWKS endpoint and edge verification
- Catalogue: platform meters, quotas and included allowances; size families c0..c3 (apps) and w1..w3 (workspaces)
- Metering for non-instance resources: resource_intervals, counter meters and quota evaluation for platform kinds
- RBAC, approvals, budgets and placement/BAA gating for platform kinds
- Event streams, event types, audit actions and SecurityEvent names for auth/storage/function/realtime/app/workspace domains
- Safety baseline for customer code in cells: node pools, Kyverno policies, seccomp, egress limits, kill switch
- Portal: Platform and Workspaces nav groups, project settings (ref, keys, JWT, primary DB, domains), API snippets panel
- CLI and MCP scaffolding for platform kinds (zb projects keys, zb auth|storage|functions|realtime|apps|ws) and client regeneration
- Admin portal: platform fleet view (functions, apps, workspaces per cell), abuse signals and per-resource kill switch
- Helm charts, image allow-lists and local dev wiring for app-auth, storage, functions, realtime, apps, workspaces and ssh-bastion
|
| E28 Agent Servers (workspaces) | Persistent cloud dev machines for coding agents: SSH bastion, web terminal, GitHub repos, snapshots, idle stop (docs/23 §5.8). | | Phase 2 · Operate at scale | - Workspace resource: API, saga and operator (pod + PVC home in its own namespace, workspace node pool, rootless Docker via sysbox, start/stop/delete, idle stop, compute and disk metering)
- SSH access: user SSH keys API/portal/CLI and the ssh-bastion service (russh) routing `ssh <workspace>@ssh.<region>.databasezy.app`
- Web terminal with tabs and a file explorer in the portal (xterm.js over WebSocket through the cell), mobile layout
|
| E24 Object storage | Buckets, objects, resumable uploads, signed URLs, S3-compatible API, image transforms, RLS policies (docs/23 §5.4). | | Phase 2 · Operate at scale | — |
| E25 Functions | TypeScript functions on deno_runtime with HTTP, cron, database, webhook and queue triggers, secrets and logs (docs/23 §5.5). | | Phase 2 · Operate at scale | — |
| E26 Realtime | Postgres changes, broadcast, presence and database webhooks over WebSocket (docs/23 §5.6). | | Phase 2 · Operate at scale | — |
| E27 Compute: apps and jobs | Containers next to the databases: image and Git-built apps, ingress, env references to instances, jobs (docs/23 §5.7). | | Phase 2 · Operate at scale | — |
| E31 Enterprise integrations | SDKs, Terraform provider, customer-side operator, BYOC cells, marketplace billing channel, audit export, open-source publication (docs/24 §7). | | Phase 2 · Operate at scale | — |
| E01 Repo, tooling and workspace | One monorepo that builds, tests and runs locally with one command. | | Complete | — |
| E06 Metering and quotas | Compute/storage/egress/backup usage, quota enforcement, capacity views. | | Complete | — |
| E07 Billing and checkout | Stripe checkout, subscriptions, usage push, dunning, entitlements. | | Complete | — |
| E09 Customer portal | Next.js portal for the full customer lifecycle. | | Complete | — |
| E14 Observability and ops | Metrics, logs, traces, synthetics, status page, on-call. | | Complete | — |
| E15 CLI and notifications | zb CLI and the notify service. | | Complete | — |
| E16 UX, responsive and accessibility | WCAG 2.2 AA, mobile-first layouts and automated a11y gates on every surface (docs/17). | | Complete | — |
| E17 Teams, seats and enterprise | Members, teams, quotas, budgets, approvals, seats, SSO/SCIM, enterprise accounts (docs/18). | | Complete | — |
| E18 Growth and developer experience | MCP server, consoles, integrations, trust surfaces. | | Complete | — |
| E23 Data APIs | Auto REST and GraphQL on Postgres via PostgREST and pg_graphql; project-keyed HTTP query API for every engine (docs/23 §5.3). | | Complete | — |